Worked example · 2023-06
MOVEit Transfer mass-extortion campaign — Cl0p — 2023-05-27 onward
Summary
On May 27, 2023, Cl0p-affiliated operators began mass-exploitation of a previously-undisclosed SQL-injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer managed-file-transfer product. The exploitation campaign deployed the LEMURLOOT custom web-shell ("human2.aspx") on compromised MOVEit Transfer instances to enable data-exfiltration without ransomware encryption — the operational model Cl0p had pivoted to in mid-2023 (a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat). The campaign scaled rapidly across MOVEit Transfer customer organisations through June 2023; CISA / FBI / NSA / U.S. Cyber Command issued joint cybersecurity advisory AA23-158A on June 7, 2023 characterising the campaign and Cl0p TTPs.
By year-end 2023 the campaign had named more than 2,500 victim organisations on the Cl0p leak site, with downstream-affected-individual records exceeding 65 million per multi-source aggregate tracking. Named victims included U.S. federal agencies (multiple Department of Energy components, Office of Personnel Management contractors), U.S. state government bodies, U.S. and U.K. private-sector enterprises across multiple sectors (PwC, EY, BBC, British Airways, Boots, U.K. payroll-services firm Zellis as a downstream-cascade source), the New York City Department of Education, the Louisiana Office of Motor Vehicles, and a long tail of cross-sector enterprise IT estates. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history per HHS, FERC, and SEC sectoral tracking.
Aggregate Cl0p-attributable extortion proceeds across the campaign per industry-forensic tracking are estimated in the $75M–$100M+ range across the campaign window through year-end 2023, with sustained tail-extortion activity continuing into 2024 and into Cl0p's subsequent mass-exploitation campaigns (TeamCity CVE-2023-42793 in late-2023 and Cleo CVE-2024-50623 / CVE-2024-55956 in late-2024). Per Coveware aggregate tracking, a majority of named victims chose not to pay; the median per-victim ransom paid was substantially below the original ask, consistent with Cl0p's data-extortion-only operating-model dynamics.
For OAK's purposes the case is the canonical worked example of mass-exploitation-of-MFT-products operational pattern and of the data-extortion-only operating-model novelty that has reshaped the post-2023 ransomware-and-data-extortion ecosystem. The campaign anchors OAK-G14 at confirmed-grade cluster attribution and at inferred-strong per-flow attribution for individual victim payments.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2020-12 to 2021-02 | Cl0p's first mass-exploitation-of-MFT-products campaign — Accellion FTA exploitation across ~100 customer organisations using CVE-2021-27101 et al; established the cluster's signature operational pattern | (precedent campaign) |
| 2023-02 | Cl0p's second mass-exploitation-of-MFT-products campaign — GoAnywhere MFT exploitation across ~130 customer organisations using CVE-2023-0669 | (precedent campaign) |
| 2023-02-08 | CISA / FBI joint cybersecurity advisory AA23-039A "#StopRansomware: CLOP Ransomware" issued ([cisa2023aa23039aclop]) |
(cluster-attribution document) |
| 2023-05-27 | Cl0p-affiliated operators begin mass-exploitation of MOVEit Transfer CVE-2023-34362; LEMURLOOT custom web-shell deployed on compromised instances for data-exfiltration | Campaign begins (off-chain entry — out of OAK Tactic scope) |
| 2023-06 | OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals ([ofac2023clopaffiliates]) |
Named-individual attribution at confirmed |
| 2023-06-07 | CISA / FBI / NSA / U.S. Cyber Command joint cybersecurity advisory AA23-158A on MOVEit campaign and Cl0p TTPs ([cisa2023aa23158aclop]) |
Cluster-attribution at confirmed |
| 2023-06 onward | Cl0p leak-site lists rapidly-growing victim cohort; victim-side disclosure tempo cascades through SEC, HHS, FERC, and adjacent sectoral regulator surfaces | (sectoral-response coordination) |
| 2023-Q3 onward | Per [coveware2023moveit] and [chainalysis2023clop], on-chain ransom-payment volume tracking against Cl0p-affiliate-controlled wallets shows aggregate proceeds in the $75M–$100M+ range; majority of named victims do not pay |
T7.002 downstream observed across cluster wallet activity |
| 2023-12 | Year-end aggregate: >2,500 named victims; downstream-affected-individual records >65 million; largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history | (campaign aggregate metrics) |
| 2024 onward | Sustained tail-extortion activity; Cl0p subsequent mass-exploitation campaigns (TeamCity, Cleo) extend the cluster's operational pattern | (continued operating tempo) |
What defenders observed
- Mass-exploitation-of-MFT-products as Cl0p's signature operational pattern. The MOVEit campaign extended Cl0p's signature mass-exploitation-of-MFT-products operational pattern from the 2020-2021 Accellion FTA campaign and the early-2023 GoAnywhere MFT campaign. Defender control-set design for MFT-product zero-day disclosure should treat Cl0p-attributable mass-exploitation as the default expectation, not as an exception. The cluster's 2024 Cleo campaign continued the pattern, demonstrating sustained operational tempo.
- Data-extortion-only operating-model novelty. Cl0p's mid-2023 pivot to data-extortion-only — encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat — is the canonical worked case in the public record for encryption-less ransomware-cluster operating model. Successor and adjacent clusters (Karakurt, BianLian, RansomHouse) have adopted variants of the data-extortion-only pattern. Defender control-set design for ransomware response now needs to assume that encryption-deployment is not the only operating model and data-disclosure-threat-only-extortion is part of the threat-actor toolkit.
- Per-victim payment-decision cascade and non-payment majority. Per Coveware aggregate tracking, a majority of named victims chose not to pay; the median per-victim ransom paid was substantially below the original ask. The aggregate-level non-payment pattern is consistent with Cl0p's data-extortion-only dynamics — without encryption, the negotiation surface is weaker against organisations whose data-archive content is not uniquely high-value or uniquely-disclosure-sensitive. Defender / CISO decision-making literature should treat aggregate non-payment as a structural feature of the data-extortion-only model.
- Sectoral-disclosure-cohort cascade. The MOVEit campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history. Sectoral regulators (SEC, HHS, FERC, FBI / CISA) coordinated cross-sector incident-disclosure tempo. Future MFT-class mass-exploitation campaigns should be expected to produce comparable sectoral-disclosure-cohort cascades.
What this example tells contributors writing future Technique pages
- Mass-exploitation campaigns produce aggregate-level on-chain attribution at confirmed-grade cluster level and inferred-strong per-flow attribution at individual-victim-payment level. Future mass-exploitation-attributable examples should expect this asymmetry. The MOVEit campaign is the canonical worked example.
- Data-extortion-only operating-model is a sustained threat-actor toolkit feature. Future ransomware-cluster attribution examples should mark whether the cluster operates in encryption-and-data-extortion (double-extortion) mode or in data-extortion-only mode; the operating-model layer materially affects defender control-set design and victim-decision dynamics.
- Industry-forensic-provider aggregate tracking is the load-bearing on-chain attribution layer for mass-extortion campaigns. Coveware / Chainalysis / TRM Labs aggregate tracking is the load-bearing on-chain attribution surface for the MOVEit campaign in the public record. Future contributors writing mass-exploitation-attribution examples should anchor on industry-forensic-provider aggregate tracking citations explicitly.
Public references
[cisa2023aa23158aclop]— Joint CISA / FBI / NSA / U.S. Cyber Command cybersecurity advisory AA23-158A on Cl0p MOVEit campaign, June 7, 2023.[cisa2023aa23039aclop]— Joint CISA / FBI cybersecurity advisory AA23-039A "#StopRansomware: CLOP Ransomware," February 8, 2023.[ofac2023clopaffiliates]— U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals.[ukrcyberpolice2021clop]— Ukrainian Cyber Police announcement of June 2021 arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement.[mandiantfin11]— Mandiant FIN11 / TA505 / Cl0p tracker write-up on operator-cohort attribution.[microsoftlacetempest]— Microsoft Threat Intelligence on Lace Tempest Cl0p-affiliated MOVEit-campaign-running sub-cluster.[coveware2023moveit]— Coveware retrospective on the MOVEit campaign victim-cohort and ransom-payment aggregates.[chainalysis2023clop]— Chainalysis forensic write-up of Cl0p downstream-laundering profile and MOVEit-campaign on-chain payment tracing.[trmlabs2023moveit]— TRM Labs forensic write-up of MOVEit-campaign Bitcoin payment tracing.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; documents Cl0p aggregate proceeds and the data-extortion-only pivot.
Discussion
The MOVEit Transfer mass-extortion campaign is the canonical worked example of Cl0p's mass-exploitation-of-MFT-products operational pattern and of the data-extortion-only operating-model novelty that has reshaped the post-2023 ransomware-and-data-extortion ecosystem. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history (>2,500 named victims, downstream-affected-individual records >65 million) and aggregate Cl0p-attributable extortion proceeds in the $75M–$100M+ range per industry-forensic tracking.
The case anchors OAK-G14 at confirmed-grade cluster attribution and at inferred-strong per-flow attribution for individual victim payments. The cluster-vs-per-flow attribution-strength asymmetry is the structural OAK observation: confirmed-grade cluster attribution rests on the multi-jurisdiction CISA / FBI / NSA / OFAC architecture and the named-individual OFAC June 2023 designations; per-flow inferred-strong attribution rests on industry-forensic-provider aggregate tracking and per-victim disclosure tempo that varies materially across the >2,500-victim cohort.
The data-extortion-only operating-model novelty is a structural feature of the post-2023 ransomware-and-data-extortion ecosystem. Defender control-set design now needs to assume that encryption-deployment is not the only operating-model and that data-disclosure-threat-only-extortion is part of the threat-actor toolkit. Future ransomware-cluster attribution examples should mark whether the cluster operates in double-extortion or data-extortion-only mode; the distinction affects defender control-set design, victim-decision dynamics, and the on-chain payment-trace public-record surface.